CVE-2026-48362
10.0Adobe · ColdFusion 2025
Adobe ColdFusion is susceptible to an OS command injection vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the underlying system.
Executive summary
An OS command injection vulnerability in Adobe ColdFusion 2025 and 2023 allows unauthenticated remote attackers to gain full system control.
Vulnerability
This is an OS command injection vulnerability (CWE-78) where the software fails to properly neutralize special elements, allowing an unauthenticated attacker to execute arbitrary system-level commands.
Business impact
A CVSS score of 10.0 highlights the severe danger of this vulnerability, which allows for total system compromise. An attacker can leverage this access to install persistent backdoors, steal sensitive business data, or disrupt critical services, leading to severe reputational and financial consequences.
Remediation
Immediate Action: Apply the vendor-provided updates by upgrading ColdFusion 2025 to 2025.0.12 and ColdFusion 2023 to 2023.0.23.
Proactive Monitoring: Monitor server processes for unusual spawning of shells or unexpected command-line activity that deviates from standard application behavior.
Compensating Controls: Utilize a Web Application Firewall (WAF) to filter out common command injection payloads targeting the ColdFusion environment.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for total system takeover, immediate patching is essential. Organizations using affected versions of Adobe ColdFusion must prioritize the deployment of the referenced security updates to protect their infrastructure.